Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2016-07-28 Locky email phishing campaign:
- Email sample (sender domain is same as recepient's domain):
- ------------------------------------------------------------------------------------------------------
- From: copier@[REDACTED]
- To: [REDACTED]
- Subject: Scanned image from copier@[REDACTED]
- Reply to: copier@[REDACTED] <copier@[REDACTED]> Device Name: copier@[REDACTED] Device Model: MX-2310U
- File Format: Microsoft Office Word
- Resolution: 200dpi x 200dpi
- Attached file is scanned image in Microsoft Office Word format.
- Use Microsoft Office Word to view the document.
- ------------------------------------------------------------------------------------------------------
- Attachment: copier@[REDACTED]_20160720265770.docm
- Attached .docm contains downloader which downloads from:
- http://aminghausen.com/j988765
- http://apachost.com/j988765
- http://avon-beraterin-mank.de/j988765
- http://baldwinhistory.portalstream.net/j988765
- http://cukiernia_izabela.republika.pl/j988765
- http://dawstaw.cba.pl/j988765
- http://dev12.gammat.net/j988765
- http://gnetgnethouse.web.fc2.com/j988765
- http://gumka.strefa.pl/j988765
- http://it4cio.servicos.ws/j988765
- http://kreacjonizm.cba.pl/j988765
- http://levivanesch.nl/j988765
- http://maka.ken-shin.net/j988765
- http://mo2radio.web.fc2.com/j988765
- http://okhtinka.ru.hoster-ok.com/j988765
- http://robertstefan.home.ro/j988765
- http://sardain.fr/j988765
- http://schefman.info/j988765
- http://sonomama.kan-be.com/j988765
- http://taityou0615.web.fc2.com/j988765
- http://tolearn.tora.ru/j988765
- http://whvf2gm5n.homepage.t-online.de/j988765
- http://www.aspadeljaen.com/j988765
- http://www.axasegurosagenciacadiz.com/j988765
- http://www.camelu.com/j988765
- http://www.centrometeosiciliano.it/j988765
- http://www.flagships.de/j988765
- http://www.kan-therm.ru/j988765
- http://www.schwarzer-baer-kastl.de/j988765
- http://www.sgspeziapallamano.com/j988765
- http://www.studiochiarelli.eu/j988765
- http://www.uasm.de/j988765
- Malware: https://www.reverse.it/sample/a7704087cfb711f2542cf7493f496d7b6719d0333db9e5bf5d716bec9531f36d?environmentId=100
- C2:
- 178.62.232.244:80/upload/_dispatch.php
- 139.59.147.0:80/upload/_dispatch.php
- 193.124.180.6:80/upload/_dispatch.php
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement